Is PKI really that complicated?

By Luther Martin —
October 14, 2011

X.509-based PKI has a reputation for being bad in many ways – expensive, hard to use, too complicated, etc.

But is it really that complicated?

To find out, I looked at the number of RFCs that the IETF's PKIX working group has published to date. Then I made the mistake of making a table of them. That took quite a while. There are actually 62 of them, which certainly seems like enough documents to make the technology qualify as "complicated."